Google's Threat Intelligence Group (GTIG) has uncovered the Coruna iPhone exploit kit, also known as 'CryptoWaters'. This sophisticated toolkit targets iOS versions 13.0 through 17.2.1, packing 23 distinct hacking methods organized into five exploit chains, some of which were previously unknown. The tool first belonged to a surveillance company, then moved to a Russian espionage group, and eventually fell into the hands of a Chinese criminal gang focused on financial theft — reflecting a growing market where state-level cyber weapons are reused by common criminals.
How the Attack Works: Fake Sites to Key Theft
Attackers lure victims with cloned cryptocurrency exchange websites, such as a fake version of WEEX. When an iPhone with a vulnerable iOS version visits the site, a hidden script runs silently in the background. The kit first checks the device model and iOS version for exploitable flaws. It then uses Safari browser vulnerabilities to gain root access. Next, a component named 'PlasmaLoader' scans the device for keywords like 'backup phrase' or 'bank account'. Finally, it targets popular wallets including MetaMask, Exodus, Coinbase Wallet, and Bitget to steal seed phrases and private keys, exfiltrating them to a hacker-controlled server.
Origin Dispute: US Government Tool Leaked?
Security firm iVerify claims the Coruna code closely resembles tools developed by the U.S. government, potentially having 'spun out of control'. However, Kaspersky experts argue there is no solid proof that the code was copied from known government frameworks. Regardless of its origin, the toolkit cost millions of dollars to develop and is now being used against ordinary users.
Industry Reaction: A Wake-Up Call for Mobile Security
The discovery signals a 'second-hand market' for cyber weapons, where state-level spy tools are recycled for financial crimes. Targeted spyware has now evolved into mass attacks against anyone holding crypto. Researchers expect hackers to become even better at hiding malicious scripts inside everyday websites.
The simplest defense is keeping iPhones updated. Google and Apple confirm that iOS 17.3 and later are not affected. For older devices that cannot be upgraded, enabling 'Lockdown Mode' stops the exploit — the kit is designed to abort if it detects Lockdown Mode, as it makes the device too hard to crack.
Cryptocurrency and mobile security involve high risks. This article is based on current security reports and does not guarantee complete protection. Always refer to official Apple security guides for device-specific advice.

